Szegedy 2013 (imperceptible perturbations)

First adversarial examples for images. Established field. Perturbations that flip predictions.

Advertisement

Goodfellow 2014 (FGSM)

Fast Gradient Sign Method. Efficient adversarial example generation. Also introduced GANs.

Advertisement

Papernot 2016 (transferability)

Adversarial examples transfer across models. Black-box attacks possible.

Madry 2018 (PGD training)

Robust training via PGD. Standard adversarial defense.